HackingStolen CredentialsTargetedIDENTITY_BASICLowContained
Cabot Risk Strategies, LLC
bd_f293c84e1bcd3059 · schema v1 · pii pii-v1
Full breach record for Cabot Risk Strategies, LLC →Cabot Risk Strategies, LLC notified consumers of a data security incident where unauthorized access occurred on April 24, 2023. The breach affected names and variable data. Cabot engaged forensic specialists, secured systems, and offered 24 months of identity theft protection. The incident status is contained.
Vermont clock✗ VT AG >45 bday15 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 7 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (6) · sorted by filing gap
- bd_171d0f19dd19cbf5New Hampshire State AGfiled 2023-08-23(1d gap)Candidate
- bd_2069dae48c53e71dMaine State AGfiled 2023-08-23(1d gap)Verified by operator
- bd_5c99c056cd275015New Hampshire State AGfiled 2023-07-26(27d gap)Verified
- bd_75caa8318a907dbeMontana State AGfiled 2023-07-26(27d gap)Candidate
Show 2 more filings ↓Show fewer ↑up to 27d gap
- bd_ef022000d5c0b51cMaine State AGfiled 2023-07-26(27d gap)Candidate
- bd_f7a2132520b8e990Vermont State AGfiled 2023-07-26(27d gap)Verified
Source provenance
- Source URL
- https://ago.vermont.gov/document/2023-08-22-cabot-risk-strategies-data-breach-notice-consumers
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 22, 2023
- Raw hash
- f50efd1cf537b3ccc93654e9ba2b98e4433eb34167468d0be534487b2510310f
Reporting entity
- Name
- Cabot Risk Strategies, LLCnorm: cabot risk strategies
- Domain
- cabotrisk.com
Victim entity
- Name
- Cabot Risk Strategies, LLCnorm: cabot risk strategies
- Domain
- cabotrisk.com
Incident
- Discovered
- May 10, 2023
- Materiality determined
- —
- Notification sent
- Aug 22, 2023
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 15 weeks(104 days from discovery to filing)
- Compliance flags
- VT AG >45 bday
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.